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(57)Abstract: 

PURPOSE: To obtain the system which speeds up 
processing without increasing definition fields while 
maintaining safety, constitutes the elliptic curve and a 
base point that facilitate combination with speeded-up 
processing by an existent additive chain, and has the 
basis of the safety for a discrete logarithmic problem on 
the elliptic curve by regarding (p) as a specific prime 
number and constituting the elliptic curve on a finite field 
GF(p). 

CONSTITUTION: For a positive integer (t) and a small 
integer a, (p) is set to the prime number which becomes 
2t±a, and a group consisting of elements on GF (p) of 
the elliptic curve E which has the finite field GF (p) as a 
definition field is denoted as E (GF (p)). When the elliptic 
curve E which is thus constituted and the base point P 
are used, the position of the base point P is divided by a 
large prime number and an MOV reduction method can 
be evaded, so the safe system is provided. Further, basic 
arithmetic operation is multiplication on GF (p), so this 

multiplication is realized faster than multiplication on a general finite field because of the form of 
p=2t±ot. Further, the multiplication can be speeded up by being combined with the method of 
the addition chain with ease. 
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H»fr»*<D*B] 

% 2t± & ttn&msit u *»i*gf (p) 

dt^ffiRfflSSEtDG F (p)±CD5c'C<tfiK$H^gf^ E 
(G F (p» t U H5IBE (G F {p))±fcmZtltz&ft*i 

[If*® 2] P £IEBi»t atf/Jx*L^jEB*alc»L 
X. 2t±aJ:**;ri**»i:U tB*GF( P )^S 
Sttd^OlgRfiJiECDG F ( P )±<D7cT*«jS*tt^il 
£ E (GF(p))£-*-£<t£. E (GF (p) ) OTtOm 
m< p less:** 5 iclirffiftRfflSE * 

[R*fl3] IEg8fed£. a-*#Q((-d)V2)©« 

*a#*aHd(x) = ocDp*ftt ufc»t i 

SSE&tfSBSafl^o 
[K*«4] IEM*tl=»LT* lEBftateftS* (2 
t) /3e^hO«*tU f8pJ2t±o:tSt 

[0001] 

LTa>l»«IBI=B***.a>"C&y* «Rffil££ 
[0 0 0 2] 

*fc«*atfBBE*ai:l** aflMB*l=a«rt*<DiE3 

s. ccds«. BEatf»*a«**iztt^ii«a»fc 

•feiittia^a*^*- ^BBi**i*a««**<*» 

o>b». aas^wt^ii********^*"*"** 1 

«><z>**-cfty. 3F»s#»oa««*ta«*s<t5 
a>i=*Rr*tt»Ba»"<?**. MWUzttB-rfii:. eft 

-< w (Neal koblitz . " A Course in Number Theory an 
d Cryptography Springer-Ver lag, 1987) inffL < 
fett-Cl**. «H*«UtO)»R»»BI«*WTI=a-< 



[0 0 0 3] <ifli»(0«K»WM 

q?*a^tL, GF(q)**B(*i:U «REftHE 
OG F (q)±(D5£-0±***t«»* E (G F (q)) 4: U 
E (G F (q))0>tt*A«*#ft*»T?*ltl'*5cP X 
*-r>l*fr*. -0>£#* E(GF(q))(D4-i&tlfc 

Q= x P 

[0 0 0 4] ±ea>*Htt»^<&BtW**BBI** 1 9 

I*. A. Menezes. S. Vanstoneand T. Okamoto. "Reduci 
ng Elliptic Curve Logarithm to Logarithms in a Fin 
ite Field*, STOC 91 (c» L < Jt^ fehtl^S. MOV 

q£*&<<£4:L. ^K(*GF(q)±S« 
£;ft*:#IRffil*£E<t E<DGF(q)±0)5E-C«** 
ft4KE(GF(q))i«. CCDt^E(GF(q))3 

Bkt q*<SlMr*3S:4:#lcl* % *B(*G F (q) CDfc^ffi 
^GF(qO ±<Dttflk**ftBBlC»» Lt* < - t 

^OiS^lCli^lSftG F ( q ) <Z>A* 6 *tt*# G F 
(q^±©»fc»*BBK»*LTB< ^t* 1 ^**. 
[0 0 0 5] f:t\ ±IB«^(DMOV4S*aSSlt^ 

fc e ^©J&attfc****. «*tf* T. Beth. F. Scha 
efer,~Non Supersingular Elliptic Curves for Public 
Key Cryptosystems ,r , Eurocrypt 91, 199k "£tcl*S 
ibftT-VOn ordinary elliptic curve cryptosystem 
s". abstract of Asiacrypt'9k *ir»L < A^#t"Cl^ 

fcft«B(*±a>»t»»BBi: R8K0)$£ttti: felitt 

[0 0 0 6] fcC54<tnft»<0»*, -36JHC12. 
3lsIomj|:£g#-f &(D"Ck 5E»{*a>**S#/h*<tt 

-3-c***y*fTa«^a<<c6ttt^. ^-wovffi 

[0 0 0 7] «|C*Rffltt*fflL^fcBt*fl)J8ffaftS* 

^^S'CM-curves with good cryptographic propertie 
s", Crypto' 91, 1991 lei* L < J&MEr^iTL**. 
[O O O 8] ftgfefll 

[0 0 0 9] #THB£#BLtt*<&tt*«0>*B*ft 
(1 ) «SRffi*§0>etia>&S 



(3) 



^l?6-2 9 5 15 4 



[0010] El : y2+ x y = x3+ x 2+1 
E2 : y 2 + x y = x 3+ 1 

*SR&|gE(DG F(2m)±CD5c-Cffl«**t^afE(G F 
( 2 no ) t lt&0> cfe 5 fcSfe fe £ o 
[0 0 1 1 ] Ei(GF(2ni))= {x, y eGF(2»n) | 
y 2+ x y = x 3+ x 2+ 1 J U {oo} 
E2(GF(2ni))= {x, yeGF(2"i) | y2+xy = x 
3+1) U [ooj 

(2) SS^ffi^:*amCD*S 

[oo 1 2] {iaA<*^^Ha^^o7cP*<ss-r^ 
[0013] (Dirgt^<fc1SR*SEiiro^r 

*(D7c0®a#E j (G F(2m))^Sft*Ha^O«j: 
5lCm^*A6*o ( i = 1 . 2) 

«nfflSEi(DGF(2m)±0)7C-C««$*t^»Ei(GF 
(2ni))(D^<7>lia$*tt^<7)ifeHa»«^fi : ftofcS^ 
m= 1 0 1 <Dt£. #E1 (G F (2 n) ) =2 x^p 
1 

m=1 3 l<Ot£ % #E2(GF(2m)) = 4 x|gap2 
[0014] «i:oTE2(GF(2l31))±(Dfia^Sap 

2<t^^7c*^-x/-t?>r>hP<t-rs«Rfte-to»a 
wapgsti l < (* e i (g f (2 ioi)) ±oeaa<stap i 

£«:*7c V K P <fc^*teREfttS±<Z>&1ife» 

[0015] z0>&5\zmmLtzmFitomt. 2*p 

(P= (x. y) ; k=1. 2. 3. 4) tDft»A<&(D 

[0016] 2P =P + P 

4P =- ( x 2~3, y 2~3) _ < x 2~2. y 2~2) 
8P =- ( x 2~3. y 2~3) + (x2~5, y 2~5) 
16P= (x2~4 y 2~4) - ( x 2~6, y 2~6) 
-»6F (2) CDffi*{*±0;H«l*. SJStLTiE^S 

So cfcoT. 2kp (k=1. 2. 3. 4) <DttJ¥a<2 
tfm&>&o E2-CI*£et*G F (2131) 



[OOI 7] L^L±Ktt*ffi|rfc^-C(*. «RffifgO> 

tb. cfcysai^-sicti, aix£Kai=r«ftit (as 

£IE8gJ££*o*rlEtt:GF (2m) ) £S£"C2i{§£ 

( 1 = 1. 2. 3. 4) tmm\~te 

(7 v ^T^^RfflS-e^o^tTX^a^^^ifea-eiil 
OM#C0^^SSfc-r«Rft«$moltS^®A< 

tiMDmom-S* E2 (GF (2131) ) <0\Z?&+ Sffifc 

fcLfcl^El (GF (2101) ) G>l$5A^*t^S<*t5 

[ooi 8] ^fc-fiftir^Rffleo)k P<Dti-ff$Si$lw 

(7)gk^§tj|:a)j!iDSffi<owSSi:^Lr**tLSo eft 

^aWS£-efe4o C*Uzoi^-Cf*. M. J. Coster. "Som 
e algorithms on addition chains and their complexi 
ty". Center for Mathematics and Computer Science R 
eport CS-R9024lci¥LLV w(D^S$ffll^fc k PCOfrS 
±&<D2'ii£& (i =1. 2. 3. 4) A<fS»lC^ 

s^^ffit^fckp<7)&ts:-eli. m&m&mi*tz&5i)< 

[OO 1 9] 

#tf)£*t<5o «t3fc«1CDcfc5I^S<Dclr»LcP^ 
SIZE: £ £ ^(Dig^ -«(7>kl::$*Lk P£Sj£ 

BITefc«. *fccP3b<SiSlzftS^#i:S*?1l**<S 

2ic^-5*#(7>M**$afc-raRffl«s«ja-rsi:sa 
mz cfc s mmit t <Dffl^ * t? * & *s r & ta& 

^K-XTK-fVhSWnKL. -^«SRffi«l±cDl8ifc»a 

[002 1] 

[Sjasss-r^fc^^^©] m&mMz&zmz. b 

SaalzWUT. p£2t±ori:fc&5£a£U <SRft 
8ES^I*GF (p) ±mtSo 
[0 0 2 2] Bt#JS2lr&£§S. ffiiiERi;%B®il(iS 

^icfc^ri*. P siEsa t si;/h*i^saaiz»L 

-C. 2t±ata**il»*a«i:L, ^RS{*G F ( p) 
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O^RffijgECDG F (p)±07cT*«tj£S*l&l* 
£E(GF(p))<h«t^, E (GF (p) ) <D7t<D® 

S£*< p left % «fc 5 I- ffifB^n ffiS E tHUSM" & o 

[0023] is*«3ir0g^s*. BKatfMM* 

^irfctNTti. IEg»d£. &-*#Q((-cl)1/2)<7) 
^!&A</h*<ft£cJ:-5l~i:y. iSp?, 4x p -1(D 

tet^GF (p) ±vd\z&*>)ttz>m&m&H 

[0 0 2 4] IS3fcJS4|z&&S£. SiE&tfS&gfite^ 

Sorli. IEB»t lc**L"C. B&* (2 t) SZMv 
^StU -hE*«tptt2t±at«-fr**»i:-r 

[0 0 2 5] 

£t/>IEgS<*lc**LT. p*2t±flffctt4*Ri:U 
tiftGF (p) ^^SttlrtoffiRftgECDGF 

(p) ±<D7tT*mtfit!tiz>m£E(GF(p))tL. me 

E (G F (p))±3e«S*tfc«1IB*»BI«*»±ttO«« 
[0 0 2 6] W*a2(c«**BBI=<fe*itf* p£IEg» 

*K(*gf ( P ) *s»»i=*-3«n*«Ea> 

GF (p) ±05£-CllWt**i*»*E (GF (p) ) t 
E (GF (p) ) (DTtOffiSLtfpKte&ko 

irisiBflfRffl^E $ t&^t zn&t Litmnttrntm 

[0 0 2 7] BI*flI3l=«**MI=«fe*ttt. lEBSd 
$ . Q ( (- d ) 1 /2) a)RK^ £ < ft & £ 5 K 

ty, SSp^s 4 x P - 1 oXBKtf d xTCBtft 
y#o. IESatai;/hSL^IESaalw>ttL-C2t±ar 

<tg-e&*»i: l. di=*ys*sajaaHd(x) = 

0Op?$t Lfc»* j ^*W=tiO*RftG F (p) * 
S«*l=*0«|Rft«E<DG F(p)±CD7C-U«jS*tL^ 
SJE(GF(p))tU fWBE(GF(p))-te«S*lfc 

[0 0 2 8] B3ft*4lc«**Wc«fc*tK. -tfBIEgS 
a(*. lEBRt lz«L-C. (2 t) /3f^ hC6W 
*#$<tL. ±B*»p I* 2 1± art ft 
y % -£(DJb-C:S:£"t:Si£ftS** Bffi&tfWBM** 
(D«f£jb<ft£*t£o 

[0 0 2 9] 

[Hlfl] ^1 ii*^^<Z)IIJ6C»l(cfclt^aRffl«±<7> 
Bffi&d««M*a®W#****^"Sfc*- 



[0 0 3 0] <1)jEB»dO>ftje 
iESSt d A^*»Q ( (- d ) V2) <DH«MW* < ft 
^xfc^let&o -C"eiid= 1 1 tt^o ftfc£-&(* 
q ((- d ) V2) XlflMWcoivci** >§" 
■y 5 7U^>f xu:7-T--f *— ^ 

X" w (J. H.Silverman, " The arithmetic of ellipt 
i c curves". Spr i nger-Ver I ag. 1 986) izW L < b *tT 

[003 1] (2)St»p0>£f£ 

iSpj, 4 P = i 1 xTORtacy. a^ojESRta 

(2 t) /3hf? hC&l^©*#*©al=»^2t- 

[O O 3 2] d 
p = 2t— a 
t =128 

or =89 25388 84800 47273 94087 
it*. 

[0 0 3 3] (3)«ntt«E*tf'<— *#-f >hP0>» 

*«ttGF(p)*je»*i::*%* 5c<7)ffla7b<Tffip<ll^ 

[0034] E:y2= x 3+12a3 x +16a4 
a=1887 65172 00252 43003 83780 59753 00282 08521 
C(Z>£#. E (GF (p) ) <7>7CP= (O. 4a2) # 

[0 0 3 5] ±B©J:5l-LTltJifcSftfc*HttBE^ 
tfK— x#-<>hPttt3l£«2a)*n«l»±©»** B 

Rjb<*£ft*R-t?«;ru jboMovjftassit^^i: 
wc»***i4»*aiw*GF ( P ) -t<D*a6u:**o 

T% p = 2t±a<^:L^5^t>— SS^KftJKD^aic 

clC^LcP ©IMUfiK < ft 4 t 5 * co-ettft 1*<D 
T% -»fl)ki:»LTk POtt*S*ai=tS¥a-e* 

tfWSfel-ft*- ^fc^-SaiCOl^Tt. S8»^>t- 
^tLtp *JtA4ft3by 1= t ar£Jt**£fc*<-e# 

[0 0 3 6] ftfi. ±fc©MS«l*jE*Rd* 1 1 fcL 

Tfrofctf. Ctt!i^ffiO£B-^{*Q((-d)1/2)<D 
SRA</]\£ <ft&£5ftIEBRft£ffiT:*c^o 
d IC« LT§kfr£mttm& P f*ii60****:ltl=B 
Sa?*i*0)-Cft< (2) ic^LfepKH^ftttSMfc 
■TSR»ft6W"e**t^o 
[0 0 3 7] 

aa>Mft3W?TBft*na»*«*"*"«^t*«-c** x 

l^±tt"C*yKiSft»** BEatfl&ffiM**©* 

a*«RTBi=ft*. 
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